Fortuity Family
Privacy notice

A child's record is not a growth channel.

This is the long version of the promises on the home page. It says what is stored, who can see it, what is never done with it, and how to take it all with you.

Covers fortuityfamily.com and the app at app.fortuityfamily.com · Updated

What is stored

Entries are appended, never overwritten. An edit or a delete is a new entry naming the one it supersedes. That is what makes two offline phones safe to merge, and it also means the record shows its own history rather than quietly rewriting it.

What is never done

  • Never sold, never shared, never rented. Not to advertisers, not to data brokers, not to anyone.
  • No advertising, anywhere.
  • No third-party analytics code of any kind on a child's record. There is no analytics SDK in the app to configure, because none is present.
  • Your baby is never compared to other babies. The product shows your child's own patterns, and never a target to hit.
  • No medical claims. It is not a medical device, does not diagnose, and does not advise on medications or doses.

One boundary stated precisely, because this is exactly the kind of line that gets blurred elsewhere: the marketing website at fortuityfamily.com measures visits with privacy-first analytics, and only after you press Accept on the banner. Choosing "Essential only" means nothing is ever sent. That is the marketing website. The app and your child's record are not part of it.

Who can see it

The caregivers you invited, and nobody else. A share link resolves to exactly one child rather than to a household or an account: that constraint is enforced in the database schema and in the sync engine, and the test suite renders a share while a decoy child exists and asserts that not one field of the decoy appears, with a positive control so a renderer that outputs nothing cannot pass by doing nothing.

An invite can be revoked. A share link can be revoked and can carry an expiry.

Taking it with you, and deleting it

Export is free and instant, on every tier including the free one, in CSV and JSON. It is not a paid feature, not a retention lever, and not something you have to ask for. A family that wants to leave gets everything on the way out.

Delete means delete, and today that is per child. A parent can remove a child from inside the app, and the rows genuinely go: every event, every share link, and the child record itself are deleted from the database rather than flagged as hidden and kept, because tombstoning would leave the payloads sitting in the table forever and that is not what the word means.

Deleting a whole household is not self-serve yet. Until it is, deleting every child in a household removes every record in it, which is the same outcome by a longer route, or write to privacy@fortuityfamily.com from the address on the account and it will be done by hand. A one-tap household delete is on the build list, and this paragraph will change when it ships.

Children, and the law

Fortuity Family is used by adults, about a child. Accounts belong to parents and caregivers; the product is not directed at children and children do not use it. The record a parent keeps about their own child belongs to that household, and this notice exists so a parent can see exactly what that record contains before deciding to keep it here.

Where it runs

On Cloudflare's platform, with the database stored there. Backups exist so that an accident is recoverable.

When this changes

The date at the top moves whenever this page does. A change that materially widens what is collected or where it goes will be announced to account holders before it takes effect, rather than discovered afterwards.